Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
strommen
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
151.
▲
by
strommen
11y ago
There are definitely cases where comments are required to describe intent...the "Why?" of the code. But the problem with comments is that they'll inevitably get out of sync with the code. And a wrong comment is far worse tha
152.
▲
by
strommen
11y ago
The 7 most-severe bugs were specifically related to reading/writing the wrong place in memory. These are impossible bugs to have in managed-memory environments. It is absolute madness to use C or C++ in a security-critical system.
153.
▲
by
strommen
11y ago
Nice work, this is really cool! But I'm kinda missing the point. I think it would be very helpful to put some corresponding C (or pseudo-C) code. I understand assembly, but it would take me forever to parse out what this program does.
154.
▲
by
strommen
11y ago
"Startup" implies venture capital, which means the founders' early understanding of the business is going to be amplified by an infusion of cash, with the expectation of rapid growth. Business success can occur slowly, perhap
155.
▲
The “Pester Your Potential Lead Until They Hate You” Approach to Sales Sucks
(moz.com)
1 points
by
strommen
11y ago
|
0 comments
156.
▲
Show HN: PerfViewer.js – load time and waterfall chart (bookmarklet-able)
(joestrommen.com)
1 points
by
strommen
11y ago
|
0 comments
157.
▲
by
strommen
11y ago
SPDY is an experimental protocol that does much of what HTTP/2 does ( you can think of it as the beta version of HTTP/2). It will be phased out starting next year over favor of the real protocol but people use it now with nginx.
158.
▲
by
strommen
11y ago
To be clear - I have no problem with this service getting shut down, as it's clearly intended to violate the user's privacy. But to say you must use APIs as "prescribed" by Apple is way too broad and subjective. I'
159.
▲
by
strommen
11y ago
> your app uses public APIs in a manner not prescribed by Apple What an enraging way to phrase this. I understand Apple's desire to shut this down, but they make their contempt for app developers obvious at every possible turn.
160.
▲
by
strommen
11y ago
This raises an interesting theoretical question: If you develop a web service and make it accessible from the public internet, what restrictions should you be allowed to place on its usage? And what should the consequences be for individua
161.
▲
by
strommen
11y ago
> The Genericons icon font package, which is used in a number of popular themes and plugins, contained an HTML file vulnerable to a cross-site scripting attack. How can an HTML file be vulnerable to XSS?
162.
▲
WordPress 4.2.2 Security and Maintenance Release
(wordpress.org)
2 points
by
strommen
11y ago
|
1 comments
163.
▲
by
strommen
11y ago
Oh come on. WCF is pretty obscure. .NET is pretty unknown to many HN readers, and even within .NET WCF is not very widely used.
164.
▲
by
strommen
11y ago
It's fascinating how async/await are spreading from C# to other languages like JavaScript and Python. As far as I know, no languages had anything like it before C# added it in ~2011. What was the last truly-new language feature t
165.
▲
by
strommen
11y ago
WCF is great if you want to make a single data service available as JSON via REST, XML via SOAP, a custom binary protocol via raw TCP, and who-knows-what else. In practice you're almost always better off just picking a single format fo
166.
▲
by
strommen
11y ago
This invention is awesome. I can't believe all the negativity in this thread for something created by a 17-year-old. So what if the technical complexity of this project isn't the super high? It's a novel approach to a real
167.
▲
by
strommen
11y ago
If you're wondering "What can I do to help Nepal from outside the country?", a former co-worker of mine (currently in Nepal) wrote about it here: https://medium.com/@amrit_sharma/what-can-i-do-to-help-nep
168.
▲
by
strommen
11y ago
The reason that BigCo never does capital-A Agile is that their release dates are fixed months ahead of time (to coordinate across the organization), and they want to know what they'll actually be shipping in 6 months (again, to coordin
169.
▲
by
strommen
11y ago
Then absolutely. Understanding functions is the biggest mental obstacle to calculus, and as programmers we already do that.
170.
▲
by
strommen
11y ago
No math like a 2-year-old? Or just simple arithmetic? Programming knowledge?
171.
▲
by
strommen
11y ago
Yes and Yes (assuming your random key isn't guessable). breachattack.com suggests masking the secret with a per-request random key, but masking the user input would work too.
172.
▲
by
strommen
11y ago
> But poorer math performance...on particularly hot days > Overlay test scores with the average temperature in the county where they lived Wait, what? Is the study about hot days or warm climates?
173.
▲
by
strommen
11y ago
Attention, everybody who publishes on the web: Selectively requiring authentication (based on referrer, user-agent, cookies, etc.) is not a supported feature of the internet. If you want to go ahead and implement it anyway, that's f
174.
▲
by
strommen
11y ago
Not really. The theory behind the attack is that if the user-specified content is equal to the secret content, it will compress more effectively and have a smaller content length. The other content on the page doesn't really matter.
175.
▲
by
strommen
11y ago
> Protocol Relative URLS are now considered an anti-pattern Sorry to sidetrack, but what's wrong with protocol-relative URLs? The only info I've found is a quote from Paul Irish relating it vaguely to the China/Github DDO
176.
▲
by
strommen
11y ago
Your app is vulnerable if it includes content from the user (e.g. a GET query parameter or something from a POST request body) in the response, and includes secret info (e.g. an anti-CSRF token) in that same response.
177.
▲
by
strommen
11y ago
Obligatory: http://imgur.com/gallery/HaKzuYU
178.
▲
Show HN: TwoStage - JavaScript and nginx to cache dynamic HTML
(twostage.io)
2 points
by
strommen
11y ago
|
0 comments
179.
▲
by
strommen
11y ago
Not exactly highbrow research, but OkCupid has an interesting post indicating that black women are less likely to get replies in their online dating service: http://blog.okcupid.com/index.php/your-race-affects-whether-.
180.
▲
by
strommen
12y ago
Similar story on the .NET side: there's a UserVoice item for "Add support for ALPN to System.Net.Security.SslStream". It's on Page 12, just behind "Improve UI for 2015 Microsoft Test Manager Client User Experience&
More ›